The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSybase Adaptive Server Enterprise
APPSybase15.7
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2016-7402CRITICAL9.8PL ✓ten sam produkt
SAP ASE: privilege escalation do SA przez SQL injection w dbcc import_sproc
CVE-2017-5371HIGH7.5ten sam produkt
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (...
CVE-2014-6284HIGH7.5ten sam produkt
SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to by...
CVE-2015-1310HIGH7.5ten sam produkt
SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute ...
CVE-2013-6859HIGH8.5ten sam produkt
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 1...